CVE-2023-23936

Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.
CRLF Injection
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
nodejsnode.js
16.0.0 ≤
𝑥
< 16.19.1
nodejsnode.js
18.0.0 ≤
𝑥
< 18.14.1
nodejsnode.js
19.0.0 ≤
𝑥
< 19.6.1
nodejsundici
2.0.0 ≤
𝑥
< 5.19.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-undici
bookworm
5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
fixed
bookworm (security)
5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
fixed
sid
5.28.4+dfsg1+~cs23.12.11-2
fixed
trixie
5.28.4+dfsg1+~cs23.12.11-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-undici
bionic
dne
focal
dne
jammy
dne
kinetic
ignored
lunar
ignored
mantic
not-affected
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs16
suse enterprise sap 15 SP4
16.19.1-150400.3.15.1
fixed
suse enterprise server 15 SP3
16.19.1-150300.7.18.1
fixed
suse enterprise server 15 SP4
16.19.1-150400.3.15.1
fixed
nodejs16-devel
suse enterprise sap 15 SP4
16.19.1-150400.3.15.1
fixed
suse enterprise server 15 SP3
16.19.1-150300.7.18.1
fixed
suse enterprise server 15 SP4
16.19.1-150400.3.15.1
fixed
nodejs16-docs
suse enterprise sap 15 SP4
16.19.1-150400.3.15.1
fixed
suse enterprise server 15 SP3
16.19.1-150300.7.18.1
fixed
suse enterprise server 15 SP4
16.19.1-150400.3.15.1
fixed
nodejs18
suse enterprise sap 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise sap 15 SP5
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP5
18.14.2-150400.9.6.2
fixed
nodejs18-devel
suse enterprise sap 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise sap 15 SP5
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP5
18.14.2-150400.9.6.2
fixed
nodejs18-docs
suse enterprise sap 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise sap 15 SP5
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP5
18.14.2-150400.9.6.2
fixed
npm16
suse enterprise sap 15 SP4
16.19.1-150400.3.15.1
fixed
suse enterprise server 15 SP3
16.19.1-150300.7.18.1
fixed
suse enterprise server 15 SP4
16.19.1-150400.3.15.1
fixed
npm18
suse enterprise sap 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise sap 15 SP5
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP4
18.14.2-150400.9.6.2
fixed
suse enterprise server 15 SP5
18.14.2-150400.9.6.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nodejs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-docs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-full-i18n
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-libs
RHEL 9
1:16.19.1-1.el9_2
fixed
nodejs-nodemon
RHEL 9
0:2.0.20-3.el9_2
fixed
npm
RHEL 9
1:8.19.3-1.16.19.1.1.el9_2
fixed